CVE-2026-29105
SuiteCRM has Unauthenticated Open Redirect in Leads WebToLead Capture
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter is used as a redirect destination without validation, allowing attackers to redirect victims to arbitrary external websites. This vulnerability allows attackers to abuse the trusted SuiteCRM domain for phishing and social engineering attacks by redirecting users to malicious external websites. Versions 7.15.1 and 8.9.3 patch the issue.
| CWE | CWE-601 |
| Vendor | suitecrm |
| Product | suitecrm |
| Published | Mar 19, 2026 |
| Last Updated | Mar 20, 2026 |
Get instant alerts for suitecrm suitecrm
Be the first to know when new medium vulnerabilities affecting suitecrm suitecrm are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N